Passed
Push — master ( c96eca...62cf55 )
by MusikAnimal
07:30
created

XtoolsController::setProject()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 4
Code Lines 2

Duplication

Lines 0
Ratio 0 %

Code Coverage

Tests 3
CRAP Score 1

Importance

Changes 0
Metric Value
cc 1
eloc 2
nc 1
nop 1
dl 0
loc 4
ccs 3
cts 3
cp 1
crap 1
rs 10
c 0
b 0
f 0
1
<?php
2
/**
3
 * This file contains the abstract XtoolsController, which all other controllers will extend.
4
 */
5
6
declare(strict_types=1);
7
8
namespace AppBundle\Controller;
9
10
use AppBundle\Exception\XtoolsHttpException;
11
use AppBundle\Helper\I18nHelper;
12
use AppBundle\Model\Page;
13
use AppBundle\Model\Project;
14
use AppBundle\Model\User;
15
use AppBundle\Repository\PageRepository;
16
use AppBundle\Repository\ProjectRepository;
17
use AppBundle\Repository\UserRepository;
18
use DateTime;
19
use Symfony\Bundle\FrameworkBundle\Controller\Controller;
20
use Symfony\Component\DependencyInjection\ContainerInterface;
21
use Symfony\Component\HttpFoundation\Cookie;
22
use Symfony\Component\HttpFoundation\JsonResponse;
23
use Symfony\Component\HttpFoundation\Request;
24
use Symfony\Component\HttpFoundation\RequestStack;
25
use Symfony\Component\HttpFoundation\Response;
26
use Symfony\Component\HttpKernel\Exception\HttpException;
27
28
/**
29
 * XtoolsController supplies a variety of methods around parsing and validating parameters, and initializing
30
 * Project/User instances. These are used in other controllers in the AppBundle\Controller namespace.
31
 * @abstract
32
 */
33
abstract class XtoolsController extends Controller
0 ignored issues
show
Deprecated Code introduced by
The class Symfony\Bundle\Framework...e\Controller\Controller has been deprecated: since Symfony 4.2, use {@see AbstractController} instead. ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-deprecated  annotation

33
abstract class XtoolsController extends /** @scrutinizer ignore-deprecated */ Controller
Loading history...
34
{
35
    /** @var I18nHelper i18n helper. */
36
    protected $i18n;
37
38
    /** @var Request The request object. */
39
    protected $request;
40
41
    /** @var string Name of the action within the child controller that is being executed. */
42
    protected $controllerAction;
43
44
    /** @var array Hash of params parsed from the Request. */
45
    protected $params;
46
47
    /** @var bool Whether this is a request to an API action. */
48
    protected $isApi;
49
50
    /** @var Project Relevant Project parsed from the Request. */
51
    protected $project;
52
53
    /** @var User Relevant User parsed from the Request. */
54
    protected $user;
55
56
    /** @var Page Relevant Page parsed from the Request. */
57
    protected $page;
58
59
    /** @var int|false Start date parsed from the Request. */
60
    protected $start = false;
61
62
    /** @var int|false End date parsed from the Request. */
63
    protected $end = false;
64
65
    /**
66
     * Default days from current day, to use as the start date if none was provided.
67
     * If this is null and $maxDays is non-null, the latter will be used as the default.
68
     * Is public visibility evil here? I don't think so.
69
     * @var int|null
70
     */
71
    public $defaultDays = null;
72
73
    /**
74
     * Maximum number of days allowed for the given date range.
75
     * Set this in the controller's constructor to enforce the given date range to be within this range.
76
     * This will be used as the default date span unless $defaultDays is defined.
77
     * @see XtoolsController::getUTCFromDateParams()
78
     * @var int|null
79
     */
80
    public $maxDays = null;
81
82
    /** @var int|string Namespace parsed from the Request, ID as int or 'all' for all namespaces. */
83
    protected $namespace;
84
85
    /** @var int Pagination offset parsed from the Request. */
86
    protected $offset = 0;
87
88
    /** @var int Number of results to return. */
89
    protected $limit;
90
91
    /** @var bool Is the current request a subrequest? */
92
    protected $isSubRequest;
93
94
    /**
95
     * Stores user preferences such default project.
96
     * This may get altered from the Request and updated in the Response.
97
     * @var array
98
     */
99
    protected $cookies = [
100
        'XtoolsProject' => null,
101
    ];
102
103
    /**
104
     * This activates the 'too high edit count' functionality. This property represents the
105
     * action that should be redirected to if the user has too high of an edit count.
106
     * @var string
107
     */
108
    protected $tooHighEditCountAction;
109
110
    /**
111
     * @var array Actions that are exempt from edit count limitations.
112
     */
113
    protected $tooHighEditCountActionBlacklist = [];
114
115
    /**
116
     * Require the tool's index route (initial form) be defined here. This should also
117
     * be the name of the associated model, if present.
118
     * @return string
119
     */
120
    abstract protected function getIndexRoute(): string;
121
122
    /**
123
     * XtoolsController constructor.
124
     * @param RequestStack $requestStack
125
     * @param ContainerInterface $container
126
     * @param I18nHelper $i18n
127
     */
128 16
    public function __construct(RequestStack $requestStack, ContainerInterface $container, I18nHelper $i18n)
129
    {
130 16
        $this->request = $requestStack->getCurrentRequest();
131 16
        $this->container = $container;
132 16
        $this->i18n = $i18n;
133 16
        $this->params = $this->parseQueryParams();
134
135
        // Parse out the name of the controller and action.
136 16
        $pattern = "#::([a-zA-Z]*)Action#";
137 16
        $matches = [];
138
        // The blank string here only happens in the unit tests, where the request may not be made to an action.
139 16
        preg_match($pattern, $this->request->get('_controller') ?? '', $matches);
0 ignored issues
show
Bug introduced by
The method get() does not exist on null. ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-call  annotation

139
        preg_match($pattern, $this->request->/** @scrutinizer ignore-call */ get('_controller') ?? '', $matches);

This check looks for calls to methods that do not seem to exist on a given type. It looks for the method on the type itself as well as in inherited classes or implemented interfaces.

This is most likely a typographical error or the method has been renamed.

Loading history...
140 16
        $this->controllerAction = $matches[1] ?? '';
141
142
        // Whether the action is an API action.
143 16
        $this->isApi = 'Api' === substr($this->controllerAction, -3) || 'recordUsage' === $this->controllerAction;
144
145
        // Whether we're making a subrequest (the view makes a request to another action).
146 16
        $this->isSubRequest = $this->request->get('htmlonly')
147 16
            || null !== $this->get('request_stack')->getParentRequest();
148
149
        // Disallow AJAX (unless it's an API or subrequest).
150 16
        $this->checkIfAjax();
151
152
        // Load user options from cookies.
153 16
        $this->loadCookies();
154
155
        // Set the class-level properties based on params.
156 16
        if (false !== strpos(strtolower($this->controllerAction), 'index')) {
157
            // Index pages should only set the project, and no other class properties.
158 10
            $this->setProject($this->getProjectFromQuery());
159
        } else {
160 6
            $this->setProperties(); // Includes the project.
161
        }
162 16
    }
163
164
    /**
165
     * Check if the request is AJAX, and disallow it unless they're using the API or if it's a subrequest.
166
     */
167 16
    private function checkIfAjax(): void
168
    {
169 16
        if ($this->request->isXmlHttpRequest() && !$this->isApi && !$this->isSubRequest) {
170
            throw new HttpException(
171
                403,
172
                $this->i18n->msg('error-automation', ['https://xtools.readthedocs.io/en/stable/api/'])
173
            );
174
        }
175 16
    }
176
177
    /***********
178
     * COOKIES *
179
     ***********/
180
181
    /**
182
     * Load user preferences from the associated cookies.
183
     */
184 16
    private function loadCookies(): void
185
    {
186
        // Not done for subrequests.
187 16
        if ($this->isSubRequest) {
188
            return;
189
        }
190
191 16
        foreach (array_keys($this->cookies) as $name) {
192 16
            $this->cookies[$name] = $this->request->cookies->get($name);
193
        }
194 16
    }
195
196
    /**
197
     * Set cookies on the given Response.
198
     * @param Response $response
199
     */
200
    private function setCookies(Response &$response): void
201
    {
202
        // Not done for subrequests.
203
        if ($this->isSubRequest) {
204
            return;
205
        }
206
207
        foreach ($this->cookies as $name => $value) {
208
            $response->headers->setCookie(
209
                new Cookie($name, $value)
210
            );
211
        }
212
    }
213
214
    /**
215
     * Sets the project, with the domain in $this->cookies['XtoolsProject'] that will
216
     * later get set on the Response headers in self::getFormattedResponse().
217
     * @param Project $project
218
     */
219 12
    private function setProject(Project $project): void
220
    {
221 12
        $this->project = $project;
222 12
        $this->cookies['XtoolsProject'] = $project->getDomain();
223 12
    }
224
225
    /****************************
226
     * SETTING CLASS PROPERTIES *
227
     ****************************/
228
229
    /**
230
     * Normalize all common parameters used by the controllers and set class properties.
231
     */
232 6
    private function setProperties(): void
233
    {
234 6
        $this->namespace = $this->params['namespace'] ?? null;
235
236
        // Offset and limit need to be ints.
237 6
        foreach (['offset', 'limit'] as $param) {
238 6
            if (isset($this->params[$param])) {
239 6
                $this->{$param} = (int)$this->params[$param];
240
            }
241
        }
242
243 6
        if (isset($this->params['project'])) {
244 2
            $this->setProject($this->validateProject($this->params['project']));
245 4
        } elseif (null !== $this->cookies['XtoolsProject']) {
246
            // Set from cookie.
247
            $this->setProject(
248
                $this->validateProject($this->cookies['XtoolsProject'])
249
            );
250
        }
251
252 6
        if (isset($this->params['username'])) {
253
            $this->user = $this->validateUser($this->params['username']);
254
        }
255 6
        if (isset($this->params['page'])) {
256
            $this->page = $this->getPageFromNsAndTitle($this->namespace, $this->params['page']);
257
        }
258
259 6
        $this->setDates();
260 6
    }
261
262
    /**
263
     * Set class properties for dates, if such params were passed in.
264
     */
265 6
    private function setDates(): void
266
    {
267 6
        $start = $this->params['start'] ?? false;
268 6
        $end = $this->params['end'] ?? false;
269 6
        if ($start || $end || null !== $this->maxDays) {
270
            [$this->start, $this->end] = $this->getUTCFromDateParams($start, $end);
271
272
            // Set $this->params accordingly too, so that for instance API responses will include it.
273
            $this->params['start'] = is_int($this->start) ? date('Y-m-d', $this->start) : false;
274
            $this->params['end'] = is_int($this->end) ? date('Y-m-d', $this->end) : false;
275
        }
276 6
    }
277
278
    /**
279
     * Construct a fully qualified page title given the namespace and title.
280
     * @param int|string $ns Namespace ID.
281
     * @param string $title Page title.
282
     * @param bool $rawTitle Return only the title (and not a Page).
283
     * @return Page|string
284
     */
285
    protected function getPageFromNsAndTitle($ns, string $title, bool $rawTitle = false)
286
    {
287
        if (0 === (int)$ns) {
288
            return $rawTitle ? $title : $this->validatePage($title);
289
        }
290
291
        // Prepend namespace and strip out duplicates.
292
        $nsName = $this->project->getNamespaces()[$ns] ?? $this->i18n->msg('unknown');
293
        $title = $nsName.':'.preg_replace('/^'.$nsName.':/', '', $title);
294
        return $rawTitle ? $title : $this->validatePage($title);
295
    }
296
297
    /**
298
     * Get a Project instance from the project string, using defaults if the given project string is invalid.
299
     * @return Project
300
     */
301 10
    public function getProjectFromQuery(): Project
302
    {
303
        // Set default project so we can populate the namespace selector on index pages.
304
        // Defaults to project stored in cookie, otherwise project specified in parameters.yml.
305 10
        if (isset($this->params['project'])) {
306 2
            $project = $this->params['project'];
307 8
        } elseif (null !== $this->cookies['XtoolsProject']) {
308
            $project = $this->cookies['XtoolsProject'];
309
        } else {
310 8
            $project = $this->container->getParameter('default_project');
311
        }
312
313 10
        $projectData = ProjectRepository::getProject($project, $this->container);
314
315
        // Revert back to defaults if we've established the given project was invalid.
316 10
        if (!$projectData->exists()) {
317
            $projectData = ProjectRepository::getProject(
318
                $this->container->getParameter('default_project'),
319
                $this->container
320
            );
321
        }
322
323 10
        return $projectData;
324
    }
325
326
    /*************************
327
     * GETTERS / VALIDATIONS *
328
     *************************/
329
330
    /**
331
     * Validate the given project, returning a Project if it is valid or false otherwise.
332
     * @param string $projectQuery Project domain or database name.
333
     * @return Project
334
     * @throws XtoolsHttpException
335
     */
336 2
    public function validateProject(string $projectQuery): Project
337
    {
338
        /** @var Project $project */
339 2
        $project = ProjectRepository::getProject($projectQuery, $this->container);
340
341 2
        if (!$project->exists()) {
342
            $this->throwXtoolsException(
343
                $this->getIndexRoute(),
344
                'invalid-project',
345
                [$this->params['project']],
346
                'project'
347
            );
348
        }
349
350 2
        return $project;
351
    }
352
353
    /**
354
     * Validate the given user, returning a User or Redirect if they don't exist.
355
     * @param string $username
356
     * @return User
357
     * @throws XtoolsHttpException
358
     */
359
    public function validateUser(string $username): User
360
    {
361
        $user = UserRepository::getUser($username, $this->container);
362
363
        // Allow querying for any IP, currently with no edit count limitation...
364
        // Once T188677 is resolved IPs will be affected by the EXPLAIN results.
365
        if ($user->isAnon()) {
366
            return $user;
367
        }
368
369
        $originalParams = $this->params;
370
371
        // Don't continue if the user doesn't exist.
372
        if (!$user->existsOnProject($this->project)) {
373
            $this->throwXtoolsException($this->getIndexRoute(), 'user-not-found', [], 'username');
374
        }
375
376
        // Reject users with a crazy high edit count.
377
        if (isset($this->tooHighEditCountAction) &&
378
            !in_array($this->controllerAction, $this->tooHighEditCountActionBlacklist) &&
379
            $user->hasTooManyEdits($this->project)
380
        ) {
381
            /** TODO: Somehow get this to use self::throwXtoolsException */
382
383
            // If redirecting to a different controller, show an informative message accordingly.
384
            if ($this->tooHighEditCountAction !== $this->getIndexRoute()) {
385
                // FIXME: This is currently only done for Edit Counter, redirecting to Simple Edit Counter,
386
                //   so this bit is hardcoded. We need to instead give the i18n key of the route.
387
                $redirMsg = $this->i18n->msg('too-many-edits-redir', [
388
                    $this->i18n->msg('tool-simpleeditcounter'),
389
                ]);
390
                $msg = $this->i18n->msg('too-many-edits', [
391
                    $this->i18n->numberFormat($user->maxEdits()),
392
                ]).'. '.$redirMsg;
393
                $this->addFlashMessage('danger', $msg);
394
            } else {
395
                $this->addFlashMessage('danger', 'too-many-edits', [
396
                    $this->i18n->numberFormat($user->maxEdits()),
397
                ]);
398
399
                // Redirecting back to index, so remove username (otherwise we'd get a redirect loop).
400
                unset($this->params['username']);
401
            }
402
403
            // Clear flash bag for API responses, since they get intercepted in ExceptionListener
404
            // and would otherwise be shown in subsequent requests.
405
            if ($this->isApi) {
406
                $this->get('session')->getFlashBag()->clear();
407
            }
408
409
            throw new XtoolsHttpException(
410
                'User has made too many edits! Maximum '.$user->maxEdits(),
411
                $this->generateUrl($this->tooHighEditCountAction, $this->params),
412
                $originalParams,
413
                $this->isApi
414
            );
415
        }
416
417
        return $user;
418
    }
419
420
    /**
421
     * Get a Page instance from the given page title, and validate that it exists.
422
     * @param string $pageTitle
423
     * @return Page
424
     * @throws XtoolsHttpException
425
     */
426
    public function validatePage(string $pageTitle): Page
427
    {
428
        $page = new Page($this->project, $pageTitle);
429
        $pageRepo = new PageRepository();
430
        $pageRepo->setContainer($this->container);
431
        $page->setRepository($pageRepo);
432
433
        if (!$page->exists()) {
434
            $this->throwXtoolsException(
435
                $this->getIndexRoute(),
436
                'no-result',
437
                [$this->params['page'] ?? null],
438
                'page'
439
            );
440
        }
441
442
        return $page;
443
    }
444
445
    /**
446
     * Throw an XtoolsHttpException, which the given error message and redirects to specified action.
447
     * @param string $redirectAction Name of action to redirect to.
448
     * @param string $message i18n key of error message. Shown in API responses.
449
     *   If no message with this key exists, $message is shown as-is.
450
     * @param array $messageParams
451
     * @param string $invalidParam This will be removed from $this->params. Omit if you don't want this to happen.
452
     * @throws XtoolsHttpException
453
     */
454
    public function throwXtoolsException(
455
        string $redirectAction,
456
        string $message,
457
        array $messageParams = [],
458
        ?string $invalidParam = null
459
    ): void {
460
        $this->addFlashMessage('danger', $message, $messageParams);
461
        $originalParams = $this->params;
462
463
        // Remove invalid parameter if it was given.
464
        if (is_string($invalidParam)) {
465
            unset($this->params[$invalidParam]);
466
        }
467
468
        // We sometimes are redirecting to the index page, so also remove project (otherwise we'd get a redirect loop).
469
        /**
470
         * FIXME: Index pages should have a 'nosubmit' parameter to prevent submission.
471
         * Then we don't even need to remove $invalidParam.
472
         * Better, we should show the error on the results page, with no results.
473
         */
474
        unset($this->params['project']);
475
476
        // Throw exception which will redirect to $redirectAction.
477
        throw new XtoolsHttpException(
478
            $this->i18n->msgIfExists($message, $messageParams),
479
            $this->generateUrl($redirectAction, $this->params),
480
            $originalParams,
481
            $this->isApi
482
        );
483
    }
484
485
    /**
486
     * Get the first error message stored in the session's FlashBag.
487
     * @return string
488
     */
489
    public function getFlashMessage(): string
490
    {
491
        $key = $this->get('session')->getFlashBag()->get('danger')[0];
492
        $param = null;
493
494
        if (is_array($key)) {
495
            [$key, $param] = $key;
496
        }
497
498
        return $this->render('message.twig', [
499
            'key' => $key,
500
            'params' => [$param],
501
        ])->getContent();
502
    }
503
504
    /******************
505
     * PARSING PARAMS *
506
     ******************/
507
508
    /**
509
     * Get all standardized parameters from the Request, either via URL query string or routing.
510
     * @return string[]
511
     */
512 16
    public function getParams(): array
513
    {
514
        $paramsToCheck = [
515 16
            'project',
516
            'username',
517
            'namespace',
518
            'page',
519
            'categories',
520
            'group',
521
            'redirects',
522
            'deleted',
523
            'start',
524
            'end',
525
            'offset',
526
            'limit',
527
            'format',
528
            'tool',
529
530
            // Legacy parameters.
531
            'user',
532
            'name',
533
            'article',
534
            'wiki',
535
            'wikifam',
536
            'lang',
537
            'wikilang',
538
            'begin',
539
        ];
540
541
        /** @var string[] $params Each parameter that was detected along with its value. */
542 16
        $params = [];
543
544 16
        foreach ($paramsToCheck as $param) {
545
            // Pull in either from URL query string or route.
546 16
            $value = $this->request->query->get($param) ?: $this->request->get($param);
547
548
            // Only store if value is given ('namespace' or 'username' could be '0').
549 16
            if (null !== $value && '' !== $value) {
550 16
                $params[$param] = rawurldecode((string)$value);
551
            }
552
        }
553
554 16
        return $params;
555
    }
556
557
    /**
558
     * Parse out common parameters from the request. These include the 'project', 'username', 'namespace' and 'page',
559
     * along with their legacy counterparts (e.g. 'lang' and 'wiki').
560
     * @return string[] Normalized parameters (no legacy params).
561
     */
562 16
    public function parseQueryParams(): array
563
    {
564
        /** @var string[] $params Each parameter and value that was detected. */
565 16
        $params = $this->getParams();
566
567
        // Covert any legacy parameters, if present.
568 16
        $params = $this->convertLegacyParams($params);
569
570
        // Remove blank values.
571 16
        return array_filter($params, function ($param) {
572
            // 'namespace' or 'username' could be '0'.
573 4
            return null !== $param && '' !== $param;
574 16
        });
575
    }
576
577
    /**
578
     * Get UTC timestamps from given start and end string parameters. This also makes $start $maxDays before
579
     * $end if not present, and makes $end the current time if not present.
580
     * The date range will not exceed $this->maxDays days, if this public class property is set.
581
     * @param int|string|false $start Unix timestamp or string accepted by strtotime.
582
     * @param int|string|false $end Unix timestamp or string accepted by strtotime.
583
     * @return int[] Start and end date as UTC timestamps.
584
     */
585 1
    public function getUTCFromDateParams($start, $end): array
586
    {
587 1
        $today = strtotime('today midnight');
588
589
        // start time should not be in the future.
590 1
        $startTime = min(
591 1
            is_int($start) ? $start : strtotime((string)$start),
592 1
            $today
593
        );
594
595
        // end time defaults to now, and will not be in the future.
596 1
        $endTime = min(
597 1
            (is_int($end) ? $end : strtotime((string)$end)) ?: $today,
598 1
            $today
599
        );
600
601
        // Default to $this->defaultDays or $this->maxDays before end time if start is not present.
602 1
        $daysOffset = $this->defaultDays ?? $this->maxDays;
603 1
        if (false === $start && is_int($daysOffset)) {
604 1
            $startTime = strtotime("-$daysOffset days", $endTime);
605
        }
606
607
        // Default to $this->defaultDays or $this->maxDays after start time if end is not present.
608 1
        if (false === $end && is_int($daysOffset)) {
609
            $endTime = min(
610
                strtotime("+$daysOffset days", $startTime),
611
                $today
612
            );
613
        }
614
615
        // Reverse if start date is after end date.
616 1
        if ($startTime > $endTime && false !== $startTime && false !== $end) {
617 1
            $newEndTime = $startTime;
618 1
            $startTime = $endTime;
619 1
            $endTime = $newEndTime;
620
        }
621
622
        // Finally, don't let the date range exceed $this->maxDays.
623 1
        $startObj = DateTime::createFromFormat('U', (string)$startTime);
624 1
        $endObj = DateTime::createFromFormat('U', (string)$endTime);
625 1
        if (is_int($this->maxDays) && $startObj->diff($endObj)->days > $this->maxDays) {
0 ignored issues
show
Bug introduced by
It seems like $endObj can also be of type false; however, parameter $datetime2 of DateTime::diff() does only seem to accept DateTimeInterface, maybe add an additional type check? ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-type  annotation

625
        if (is_int($this->maxDays) && $startObj->diff(/** @scrutinizer ignore-type */ $endObj)->days > $this->maxDays) {
Loading history...
626
            // Show warnings that the date range was truncated.
627 1
            $this->addFlashMessage('warning', 'date-range-too-wide', [$this->maxDays]);
628
629 1
            $startTime = strtotime("-$this->maxDays days", $endTime);
630
        }
631
632 1
        return [$startTime, $endTime];
633
    }
634
635
    /**
636
     * Given the params hash, normalize any legacy parameters to their modern equivalent.
637
     * @param string[] $params
638
     * @return string[]
639
     */
640 16
    private function convertLegacyParams(array $params): array
641
    {
642
        $paramMap = [
643 16
            'user' => 'username',
644
            'name' => 'username',
645
            'article' => 'page',
646
            'begin' => 'start',
647
648
            // Copy super legacy project params to legacy so we can concatenate below.
649
            'wikifam' => 'wiki',
650
            'wikilang' => 'lang',
651
        ];
652
653
        // Copy legacy parameters to modern equivalent.
654 16
        foreach ($paramMap as $legacy => $modern) {
655 16
            if (isset($params[$legacy])) {
656
                $params[$modern] = $params[$legacy];
657 16
                unset($params[$legacy]);
658
            }
659
        }
660
661
        // Separate parameters for language and wiki.
662 16
        if (isset($params['wiki']) && isset($params['lang'])) {
663
            // 'wikifam' will be like '.wikipedia.org', vs just 'wikipedia',
664
            // so we must remove leading periods and trailing .org's.
665
            $params['project'] = rtrim(ltrim($params['wiki'], '.'), '.org').'.org';
666
667
            /** @var string[] $languagelessProjects Projects for which there is no specific language association. */
668
            $languagelessProjects = $this->container->getParameter('languageless_wikis');
669
670
            // Prepend language if applicable.
671
            if (isset($params['lang']) && !in_array($params['wiki'], $languagelessProjects)) {
672
                $params['project'] = $params['lang'].'.'.$params['project'];
673
            }
674
675
            unset($params['wiki']);
676
            unset($params['lang']);
677
        }
678
679 16
        return $params;
680
    }
681
682
    /************************
683
     * FORMATTING RESPONSES *
684
     ************************/
685
686
    /**
687
     * Get the rendered template for the requested format. This method also updates the cookies.
688
     * @param string $templatePath Path to template without format,
689
     *   such as '/editCounter/latest_global'.
690
     * @param array $ret Data that should be passed to the view.
691
     * @return Response
692
     * @codeCoverageIgnore
693
     */
694
    public function getFormattedResponse(string $templatePath, array $ret): Response
695
    {
696
        $format = $this->request->query->get('format', 'html');
697
        if ('' == $format) {
698
            // The default above doesn't work when the 'format' parameter is blank.
699
            $format = 'html';
700
        }
701
702
        // Merge in common default parameters, giving $ret (from the caller) the priority.
703
        $ret = array_merge([
704
            'project' => $this->project,
705
            'user' => $this->user,
706
            'page' => $this->page,
707
        ], $ret);
708
709
        $formatMap = [
710
            'wikitext' => 'text/plain',
711
            'csv' => 'text/csv',
712
            'tsv' => 'text/tab-separated-values',
713
            'json' => 'application/json',
714
        ];
715
716
        $response = new Response();
717
718
        // Set cookies. Note this must be done before rendering the view, as the view may invoke subrequests.
719
        $this->setCookies($response);
720
721
        // If requested format does not exist, assume HTML.
722
        if (false === $this->get('twig')->getLoader()->exists("$templatePath.$format.twig")) {
723
            $format = 'html';
724
        }
725
726
        $response = $this->render("$templatePath.$format.twig", $ret, $response);
727
728
        $contentType = $formatMap[$format] ?? 'text/html';
729
        $response->headers->set('Content-Type', $contentType);
730
731
        if (in_array($format, ['csv', 'tsv'])) {
732
            $filename = $this->getFilenameForRequest();
733
            $response->headers->set(
734
                'Content-Disposition',
735
                "attachment; filename=\"{$filename}.$format\""
736
            );
737
        }
738
739
        return $response;
740
    }
741
742
    /**
743
     * Returns given filename from the current Request, with problematic characters filtered out.
744
     * @return string
745
     */
746
    private function getFilenameForRequest(): string
747
    {
748
        $filename = trim($this->request->getPathInfo(), '/');
749
        return trim(preg_replace('/[-\/\\:;*?|<>%#"]+/', '-', $filename));
750
    }
751
752
    /**
753
     * Return a JsonResponse object pre-supplied with the requested params.
754
     * @param array $data
755
     * @return JsonResponse
756
     */
757 2
    public function getFormattedApiResponse(array $data): JsonResponse
758
    {
759 2
        $response = new JsonResponse();
760 2
        $response->setEncodingOptions(JSON_NUMERIC_CHECK);
761 2
        $response->setStatusCode(Response::HTTP_OK);
762
763 2
        $elapsedTime = round(
764 2
            microtime(true) - $this->request->server->get('REQUEST_TIME_FLOAT'),
765 2
            3
766
        );
767
768
        // Any pipe-separated values should be returned as an array.
769 2
        foreach ($this->params as $param => $value) {
770 2
            if (is_string($value) && false !== strpos($value, '|')) {
771 2
                $this->params[$param] = explode('|', $value);
772
            }
773
        }
774
775 2
        $ret = array_merge($this->params, [
776
            // In some controllers, $this->params['project'] may be overridden with a Project object.
777 2
            'project' => $this->project->getDomain(),
778 2
        ], $data, ['elapsed_time' => $elapsedTime]);
779
780
        // Merge in flash messages, putting them at the top.
781 2
        $flashes = $this->get('session')->getFlashBag()->peekAll();
782 2
        $ret = array_merge($flashes, $ret);
783
784
        // Flashes now can be cleared after merging into the response.
785 2
        $this->get('session')->getFlashBag()->clear();
786
787 2
        $response->setData($ret);
788
789 2
        return $response;
790
    }
791
792
    /*********
793
     * OTHER *
794
     *********/
795
796
    /**
797
     * Record usage of an API endpoint.
798
     * @param string $endpoint
799
     * @codeCoverageIgnore
800
     */
801
    public function recordApiUsage(string $endpoint): void
802
    {
803
        /** @var \Doctrine\DBAL\Connection $conn */
804
        $conn = $this->container->get('doctrine')
805
            ->getManager('default')
806
            ->getConnection();
807
        $date =  date('Y-m-d');
808
809
        // Increment count in timeline
810
        $existsSql = "SELECT 1 FROM usage_api_timeline
811
                      WHERE date = '$date'
812
                      AND endpoint = '$endpoint'";
813
814
        if (0 === count($conn->query($existsSql)->fetchAll())) {
815
            $createSql = "INSERT INTO usage_api_timeline
816
                          VALUES(NULL, '$date', '$endpoint', 1)";
817
            $conn->query($createSql);
818
        } else {
819
            $updateSql = "UPDATE usage_api_timeline
820
                          SET count = count + 1
821
                          WHERE endpoint = '$endpoint'
822
                          AND date = '$date'";
823
            $conn->query($updateSql);
824
        }
825
    }
826
827
    /**
828
     * Add a flash message.
829
     * @param string $type
830
     * @param string $key i18n key or raw message.
831
     * @param array $vars
832
     */
833 1
    public function addFlashMessage(string $type, string $key, array $vars = []): void
834
    {
835 1
        $this->addFlash(
836 1
            $type,
837 1
            $this->i18n->msgExists($key, $vars) ? $this->i18n->msg($key, $vars) : $key
0 ignored issues
show
Bug introduced by
It seems like $this->i18n->msgExists($...msg($key, $vars) : $key can also be of type null; however, parameter $message of Symfony\Bundle\Framework...\Controller::addFlash() does only seem to accept string, maybe add an additional type check? ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-type  annotation

837
            /** @scrutinizer ignore-type */ $this->i18n->msgExists($key, $vars) ? $this->i18n->msg($key, $vars) : $key
Loading history...
838
        );
839 1
    }
840
}
841